Vulnerabilities > Atlassian > Jira Service Management

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2023-22501 Improper Authentication vulnerability in Atlassian Jira Service Management
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into.
network
low complexity
atlassian CWE-287
critical
9.1
2022-08-03 CVE-2022-36800 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint.
network
low complexity
atlassian
4.3
2022-07-26 CVE-2021-43959 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Service Desk and Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight.
network
low complexity
atlassian CWE-918
5.7
2022-07-20 CVE-2022-26136 Improper Authentication vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.
network
low complexity
atlassian CWE-287
critical
9.8
2022-07-20 CVE-2022-26137 Origin Validation Error vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses.
network
low complexity
atlassian CWE-346
8.8
2022-06-30 CVE-2022-26135 Server-Side Request Forgery (SSRF) vulnerability in Atlassian products
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.
network
low complexity
atlassian CWE-918
6.5
2022-04-20 CVE-2022-0540 Unspecified vulnerability in Atlassian Jira Data Center and Jira Service Management
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request.
network
low complexity
atlassian
critical
9.8
2022-02-24 CVE-2021-43943 Cross-site Scripting vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa.
network
low complexity
atlassian CWE-79
4.8
2022-02-15 CVE-2021-43948 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature.
network
low complexity
atlassian
4.3
2022-02-15 CVE-2021-43950 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature.
network
low complexity
atlassian
4.3